AI agents can chain credentials and tools to reach beyond direct permissions, as a Hugging Face evaluation showed.
Bifrost CVE-2026-90898 enables unauthenticated command execution with management auth disabled; transports/v2.1.0 fixes the flaw.
BigDiskBuster can block Microsoft Defender updates by filling disk space, leaving detection content stale; no patch or advisory exists.
North Korean Contagious Interview campaign compromised 30,000 devices and stole at least $10.71 million in cryptocurrency.
Attackers are exploiting CVE-2026-93952 in certificate-authenticated VeloCloud Orchestrators, with some release trains still awaiting fixes.
A Linux KVM flaw on ARM64 can expose host kernel memory to guests and enable guest-to-host escape when nested virtualization is enabled.
SharePoint CVE-2026-65660 enables authenticated RCE; Microsoft patched it on August 11, and no in-the-wild exploitation is reported.
CISA added Zyxel CVE-2026-7273 to KEV after active exploitation, while Arctic Wolf reported attacks on a Veeam Windows flaw.
SideCopy targets Indian academic institutions with spear-phishing that abuses mshta.exe to deploy ReverseRAT for collection and remote access.
DORA’s second year shifts focus to proving ICT controls work, with network evidence supporting monitoring, detection, and incident response.
WordPress fixed a comment flaw that could lead to server code execution if a logged-in administrator opened the page.
A Mac Muse flaw lets malware running as the logged-in user reroute dictation, inject instructions, and steal the assistant's session token.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results